Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

ubuntu логотип

CVE-2016-3956

Опубликовано: 02 июл. 2016
Источник: ubuntu
Приоритет: medium
EPSS Низкий
CVSS2: 5
CVSS3: 7.5

Описание

The CLI in npm before 2.15.1 and 3.x before 3.8.3, as used in Node.js 0.10 before 0.10.44, 0.12 before 0.12.13, 4 before 4.4.2, and 5 before 5.10.0, includes bearer tokens with arbitrary requests, which allows remote HTTP servers to obtain sensitive information by reading Authorization headers.

РелизСтатусПримечание
artful

ignored

end of life
bionic

ignored

end of standard support, was needed
cosmic

not-affected

3.8.3
devel

not-affected

3.8.3
disco

not-affected

3.8.3
eoan

not-affected

3.8.3
esm-apps-legacy/xenial

released

3.5.2-0ubuntu4.1.16.04.1~esm1
esm-apps/bionic

released

3.5.2-0ubuntu4.1.18.04.1~esm1
esm-apps/focal

not-affected

3.8.3
esm-apps/jammy

not-affected

3.8.3

Показывать по

EPSS

Процентиль: 93%
0.06748
Низкий

5 Medium

CVSS2

7.5 High

CVSS3

Связанные уязвимости

redhat
больше 10 лет назад

The CLI in npm before 2.15.1 and 3.x before 3.8.3, as used in Node.js 0.10 before 0.10.44, 0.12 before 0.12.13, 4 before 4.4.2, and 5 before 5.10.0, includes bearer tokens with arbitrary requests, which allows remote HTTP servers to obtain sensitive information by reading Authorization headers.

CVSS3: 7.5
nvd
около 10 лет назад

The CLI in npm before 2.15.1 and 3.x before 3.8.3, as used in Node.js 0.10 before 0.10.44, 0.12 before 0.12.13, 4 before 4.4.2, and 5 before 5.10.0, includes bearer tokens with arbitrary requests, which allows remote HTTP servers to obtain sensitive information by reading Authorization headers.

CVSS3: 7.5
debian
около 10 лет назад

The CLI in npm before 2.15.1 and 3.x before 3.8.3, as used in Node.js ...

github
почти 8 лет назад

npm Token Leak in npm

EPSS

Процентиль: 93%
0.06748
Низкий

5 Medium

CVSS2

7.5 High

CVSS3